ee5eb5a960
For L4/tcp exported services the mesh gateways will not be terminating TLS. A caller in one peer will be directly establishing TLS connections to the ultimate exported service in the other peer. The caller will be doing SAN validation using the replicated SpiffeID values shipped from the exporting side. There are a class of discovery chain edits that could be done on the exporting side that would cause the introduction of a new SpiffeID value. In between the time of the config entry update on the exporting side and the importing side getting updated peer stream data requests to the exported service would fail due to SAN validation errors. This is unacceptable so instead prohibit the exporting peer from making changes that would break peering in this way. |
||
---|---|---|
.. | ||
acl.go | ||
acl_events.go | ||
acl_events_test.go | ||
acl_oss.go | ||
acl_oss_test.go | ||
acl_schema.go | ||
acl_test.go | ||
autopilot.go | ||
autopilot_test.go | ||
catalog.go | ||
catalog_events.go | ||
catalog_events_oss.go | ||
catalog_events_oss_test.go | ||
catalog_events_test.go | ||
catalog_oss.go | ||
catalog_oss_test.go | ||
catalog_schema.go | ||
catalog_test.go | ||
config_entry.go | ||
config_entry_events.go | ||
config_entry_events_test.go | ||
config_entry_intention.go | ||
config_entry_intention_oss.go | ||
config_entry_oss.go | ||
config_entry_oss_test.go | ||
config_entry_schema.go | ||
config_entry_test.go | ||
connect_ca.go | ||
connect_ca_events.go | ||
connect_ca_events_test.go | ||
connect_ca_test.go | ||
coordinate.go | ||
coordinate_oss.go | ||
coordinate_oss_test.go | ||
coordinate_test.go | ||
delay_oss.go | ||
delay_test.go | ||
events.go | ||
federation_state.go | ||
graveyard.go | ||
graveyard_oss.go | ||
graveyard_test.go | ||
index_connect_test.go | ||
indexer.go | ||
intention.go | ||
intention_oss.go | ||
intention_test.go | ||
kvs.go | ||
kvs_oss.go | ||
kvs_oss_test.go | ||
kvs_test.go | ||
memdb.go | ||
operations_oss.go | ||
peering.go | ||
peering_oss.go | ||
peering_oss_test.go | ||
peering_test.go | ||
prepared_query.go | ||
prepared_query_index.go | ||
prepared_query_index_test.go | ||
prepared_query_test.go | ||
query.go | ||
query_oss.go | ||
schema.go | ||
schema_oss.go | ||
schema_oss_test.go | ||
schema_test.go | ||
session.go | ||
session_oss.go | ||
session_test.go | ||
state_store.go | ||
state_store_oss_test.go | ||
state_store_test.go | ||
store_integration_test.go | ||
system_metadata.go | ||
system_metadata_test.go | ||
tombstone_gc.go | ||
tombstone_gc_test.go | ||
txn.go | ||
txn_test.go | ||
usage.go | ||
usage_oss.go | ||
usage_test.go |